CVE 3.1 LOW

Cross-team channel membership access_CVE-2025-11777

3.1 / 10
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Description

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API which allows users from one team to access user metadata and channel membership information from other teams via the API endpoint

Basic Information

ID CVE-2025-11777
Source Mattermost
Published Nov 13, 2025 at 17:32
Modified Nov 13, 2025 at 18:01

Affected Product

Vendor Mattermost
Product Mattermost
Version 10.11.0
Affected Versions Mattermost Mattermost 10.11.0
Mattermost Mattermost 10.5.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.